LIVE · cybersecurity feed
Live wire
cve record

CVE-2026-4368

Published
CVSS
Severitynone
WeaknessCWE-362
ExploitedNot in CISA KEV

Description

Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup

References

← Back to the CVE Tracker

Our coverage of CVE-2026-4368

CVE-2026-19490critical

Critical Citrix NetScaler auth bypass now leveraged in attacks

Attackers are actively exploiting a critical authentication bypass vulnerability in Citrix NetScaler appliances, tracked as CVE-2026-19490. The flaw allows unprivileged actors to bypass authentication remotely under specific configuration conditions. Security researchers have observed exploitation attempts from multiple countries, prompting warnings from cybersecurity agencies urging immediate patching of affected devices.